Vulnerability CVE-2022-31814


Published: 2022-09-05

Description:
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

See advisories in our WLB2 database:
Topic
Author
Date
High
pfBlockerNG 2.1.4_26 Remote Code Execution
IHTeam
27.02.2023

 References:
https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html

Copyright 2024, cxsecurity.com

 

Back to Top